Information Security Officer Jobs
Information Security Officer jobs are open across financial services, healthcare, government, and technology, at every level from analyst to CISO, with specializations in risk management, compliance, and incident response. Find a role that fits from the openings below and apply directly.
Find JobsOverview
Showing 5 of 63+ Information Security Officer jobs











IMPORTANT APPLICATION INSTRUCTIONS:
- Upload Resume or Curriculum Vitae for automatic population of information to the application.
- The contact information, work experience, and education listed on your Resume/CV will be parsed and input into your Montclair application.
- Review information and double-check all fields containing information that the system parsed – the software is intelligent, but you need to verify that the data is accurate.
- In the “My Experience” section, you will find a Resume/CV upload option where you can submit your cover letter and all other supporting documents.
Note: If you have an expansive CV, we recommend that you apply manually and only include the positions you have held in the last ten (10) years. You will then be able to attach your Resume/CV, as well as all other supporting documentation in the "My Experience" section of your application.
Job Description
SUMMARY
Reporting to the Deputy CIO of Information Technology, the Chief Information Security Officer (CISO) is a member of the Information Technology (IT) leadership team and works closely with senior administration, academic leaders, and the campus community. The CISO is the lead advocate for the institution's information and cyber security needs and is responsible for the development and oversight of a comprehensive information security strategy intended to protect information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction and to provide confidentiality, integrity, and availability.
As a member of the IT leadership team, the CISO leads the development, implementation, and oversight of an information and cyber security program to protect campus-wide resources, facilitates information security governance, advises senior leadership on security matters and resource investments, and writes appropriate policies to manage information security risk. The CISO is responsible for recommending and coordinating the planning, implementation, enforcement, and troubleshooting activities that ensure the security and integrity of the University’s overall information systems and data assets. The complexity of this position requires a leadership approach that is engaging, imaginative, and collaborative, with a sophisticated ability to work with University systems and campus leaders to optimize the information security posture of the University.
This position directly manages a team of information and cybersecurity staff and also has authority to create ad hoc working groups among other central and distributed IT staff as needed to ensure that the University's overall computing and network policies, procedures, and infrastructure design adhere to information security best practice principles. The CISO is a visible/communicative leader on campus and off-campus by representing Montclair to the global higher education community.
PRINCIPAL DUTIES AND RESPONSIBILITIES:
University and Program Leadership:
- Provide guidance and counsel to the CIO and key members of the University leadership team regarding information security and privacy issues, risks, mitigation strategies, and information security governance.
- Develop a comprehensive information security program with annual and long-range security and compliance goals, metrics, reporting mechanisms, and program services.
- Develop and lead outreach, communication, and user education efforts to promote campus-wide information and cybersecurity awareness.
- Collaborate with IT leadership on incorporating information security throughout the technology life cycle, risk management, and audit compliance to provide adequate protection for campus hosted information resources.
- Build positive relationships and foster goodwill towards efforts to improve overall security posture.
- Review hardware, software, and services being considered for purchase or implementation by IT or other campus departments to assess potential security risks and ensure proper information security features are incorporated to address university requirements.
- Maintain integrity and appropriate confidentiality of information security related matters.
- Provide supervision for team resources, as well as budget development and management as needed.
Policy, Compliance and Audit:
- Develop, implement and oversee policies, standards and processes.
- Serve as the University’s primary point of contact in all audit, compliance, insurance, or legal matters related to information security.
- Keep abreast of changes to the State, Federal, and industry regulations that can impact University operations such as HIPAA, PCI-DSS, EUGDPR, FERPA, Red Flags, and Gramm-Leach-Bliley. Make recommendations for changes or additions to university policies, procedures, or technology infrastructure to support compliance with these regulations from an information security perspective.
- Create ad-hoc functional teams from among the various central and distributed IT units to research, recommend, and deploy new information security technologies or to implement changes to existing policies and procedures.
Risk Management and Incident response:
- Oversee IT security risk assessment processes. Coordinates annual or periodic information security risk assessment reviews as necessary or required for institutional auditing purposes.
- Develop a roadmap to reduce high risks and sustain a well-controlled environment to protect information assets.
- Oversee information security incident response, serving as incident coordinator and forming ad hoc incident response teams as necessary to respond to and recover from potential security incidents or data breaches.
- Develop and lead new information security initiatives.
- Communicate and coordinate with the Chief Information Officer and other campus leadership as appropriate during incident response activities. Escalate incidents, when appropriate, to executive team for determination of information security breach and notification.
- Coordinate contracted relationships with external security service providers for a variety of needs including digital forensics investigations, e-Discovery, or other sensitive data analysis as requested by IT management, Legal Counsel, Human Resources, or appropriate University officials.
Outreach, Education and Training:
- Provide leadership in identifying, developing, implementing and maintaining information security awareness, as well as general and specialized training programs for the University.
- Recruit, hire, train and mentor the Information Security staff and implement professional development plans for all members of the team as needed.
- Oversee security operations related activities and manage the relationship with the MDR partner (Red Canary) including monthly review of reports and vulnerability mitigation strategies in the broader landscape.
QUALIFICATIONS
REQUIRED:
- A Bachelor's degree from an accredited college or university.
- Cyber security industry certifications from an established organization, such as SANS.
- A minimum of ten (10) years of progressively responsible IT experience with a minimum of five (5) years of managerial experience.
- Professional experience designing, implementing, and/or managing information security policies, procedures, and solutions.
- Broad knowledge of computer security issues, requirements, and trends.
- Strong interpersonal and communication skills, plus the ability to achieve goals through influence, collaboration and cooperation.
- Demonstrated ability to work effectively with an array of constituencies in a community that is both demographically and technologically diverse.
- Experience providing education and training programs on security policies and practices to a range of technical and non-technical constituents.
- Experience evaluating and providing guidance on the information security elements of software and hardware acquisitions, IT services, cloud-based solutions, mobility, and other present and emerging aspects of IT solutions and services in a complex environment.
- Referenceable integrity and high standards of personal and professional conduct.
PREFERRED:
- Master's degree or other relevant formal education.
- Minimum five years of experience in a higher education IT environment.
- Ability to explain highly technical topics in terms that can be understood by a less technical audience.
- Strong organizational skills and a successful track record of effective coordination, prioritization, collaboration, and project delivery.
- An understanding of current legislation and regulations pertaining to higher education institutions (i.e. HIPAA, PCI-DSS, EUGDPR, FERPA, Red Flags, and Gramm-Leach-Bliley).
- Is professionally active by presenting at conferences and/or publishing/contributing to timely Information Security articles.
PROCEDURE FOR CANDIDACY
Applicants should include a resume and cover letter describing how their background, skills and education match the needs of the University. When applying, please take a moment to carefully read and follow the steps in the application instructions.
Salary Range
$195,000.00-$206,000.00 Annually
The position may also be eligible for comprehensive benefits, including health insurance, retirement plans, and tuition assistance. For further details, please visit: https://www.montclair.edu/human-resources/benefits/
Montclair State University considers factors such as, but not limited to, scope and responsibilities of the position, candidate’s relevant work experience, education, skills, and internal equity, when extending an offer.
Salary offers for internal employees who are part of a collective bargaining unit (CBU) and are applying to a position that is within a CBU will be determined in accordance with contractual provisions.
Department
Office of the Deputy CIO Information Technology
Position Type
Administrative
Contact Information:
For questions or concerns, please contact Human Resources' Workday Recruiting Support at 973-655-5000 (Option 2), or email talent@montclair.edu.
Inclusion Statement
Montclair State University values access and educational excellence. We are committed to an environment of diverse perspectives which ensures that graduates will be civically engaged, committed to democracy, and prepared to thrive as global citizens. We foster a community that promotes varied experiences and voices. We seek applicants who will contribute diverse ideas and perspectives and who value an environment that promotes educational growth and advancement for all.
EEO/AA Statement
Montclair State University is an Equal Opportunity/Affirmative Action institution with a strong commitment to diversity.
Additional information can be found on the website at
www.montclair.edu/human-resources/about-us/eo-aa-and-diversity/
Title IX and 34 C.F.R. 106 Policy
Montclair State is required by Title IX and 34 C.F.R. 106 not to discriminate on the basis of sex or gender, and does not discriminate on the basis of sex or gender in the operation of education programs and activities. The requirement to not discriminate on the basis of sex or gender in the operation of education programs and activities extends to admission and employment. For further details, please visit: https://www.montclair.edu/human-resources/job-seekers/
See All 63+ Information Security Officer Jobs
Jump back to the full list of openings and apply to any information security officer role that fits.
Find JobsInformation Security Officer Job Market
A snapshot from current openings nationwide, updated as new roles post.
Who's Hiring
- Bank of China USA9

- Vanta4

- Gainwell Technologies3

- First American2

- Rush University Medical Center2

Top Industries Hiring
- Banking & Financial Services19
- Technology & Software15
- Education8
- Healthcare & Medical Services7
- Consulting & Professional Services5
What Employers Look For
The qualifications that appear most often in information security officer jobs.
- CISSP, CISM, or equivalent security certification strongly preferred or required
- Proven experience building or leading an information security program
- Deep knowledge of risk management frameworks such as NIST CSF or ISO 27001
- Familiarity with regulatory compliance requirements including SOX, HIPAA, or PCI-DSS
- Experience conducting or overseeing security audits and vulnerability assessments
- Bachelor's degree in information security, computer science, or a related field
Tips for Your Information Security Officer Job Search
Align certifications to the posting
Many information security officer roles list CISSP, CISM, or CRISC as requirements, not preferences. Match the exact certification acronyms from the job description in your resume header and skills section so automated screening tools pick them up immediately.
Quantify risk reduction outcomes
Hiring managers in this role respond to concrete impact. Replace vague statements like 'managed security programs' with specifics about audit findings reduced, vulnerabilities remediated within a defined window, or compliance gaps closed before a regulatory deadline.
Apply early to roles that fit
Migrate Mate lists information security officer openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Target industries by your compliance background
Financial services roles prioritize SOX and PCI-DSS experience while healthcare roles weight HIPAA program ownership heavily. Tailor your resume's summary and experience bullets to the regulatory framework that dominates the industry you're targeting.
Prepare a governance artifact for interviews
Bring or be ready to discuss a policy, framework, or risk register you authored. Information security officer interviews often include a scenario where you walk through how you structured a program, not just what certifications you hold.
Negotiate scope before you negotiate salary
Clarify reporting structure, board access, and budget authority during the offer stage. An information security officer title without executive access or a dedicated budget limits your ability to deliver results and constrains future career advancement.
Information Security Officer Jobs: Frequently Asked Questions
Which companies are hiring the most information security officers?
The companies hiring the most information security officers right now include Bank of China USA, Vanta, and Gainwell Technologies, with the largest share of openings in New York, California, and Texas, based on current listings on Migrate Mate as of June 2026. Demand is concentrated in financial services, federal contracting, and large healthcare systems.
How many information security officer jobs are remote?
About 32% of information security officer openings are fully remote or hybrid as of June 2026, though fully on-site roles remain common in government and regulated industries. Risk and compliance-focused sub-areas of the role tend to offer the most remote flexibility, while roles tied to physical infrastructure or classified environments typically require on-site presence.
How do you become an information security officer?
Start by building a foundation in IT or cybersecurity through hands-on roles such as security analyst, systems administrator, or network engineer. Earn a recognized certification like CISSP or CISM, then move into program ownership by leading audits, drafting security policies, or managing compliance initiatives. Progressing to an information security officer role typically requires demonstrated leadership over a security function, not just technical execution.
Can you get an information security officer job with little or no experience?
Direct information security officer roles generally require prior security program experience, but you can build toward them by starting in analyst, IT risk, or compliance roles that expose you to policy development and audit processes. Earning a foundational certification, contributing to a security assessment, or owning a discrete compliance workstream in a smaller organization can position you for an officer-level role faster than a traditional linear path.
What does the information security officer interview process look like?
Most information security officer hiring processes include an initial screening call, a technical or competency interview covering risk frameworks and past program decisions, and a final round with executive stakeholders such as the CFO or CTO. Candidates are often asked to present a past security initiative or respond to a scenario involving a breach, a compliance gap, or a board-level risk briefing.
Where can I find and apply to information security officer jobs?
You can find and apply to information security officer jobs on Migrate Mate, which lists current openings from across the United States. Find roles that match your experience and specialization, then apply directly to each listing without being redirected to third-party sites.
See All 63+ Information Security Officer Jobs
Jump back to the full list of openings and apply to any information security officer role that fits.
Find Jobs